The revised Swiss data protection act, read practically
The revised FADP has applied since 1 September 2023, with no transition period. For most SMEs the workload is smaller than feared — but in one respect it is less comfortable than the GDPR: the fine falls on the responsible person, not the company.
Short answers
- Since when?
- 1 September 2023, with no transition period. The 1992 act was replaced outright.
- Who does it protect?
- Natural persons only. Data about legal entities — protected under the old act — no longer falls within scope.
- Do we need a record of processing activities?
- Companies with fewer than 250 employees are generally exempt, provided the processing carries low risk and sensitive personal data is not processed at scale.
- How large are the fines?
- Up to CHF 250,000 — and they are directed at the responsible natural person, not the company. That is the central difference from the GDPR.
- Can we send customer documents by email?
- The act prohibits no channel. It requires measures appropriate to the risk. For documents containing personal data a mailbox is weak control: no revocation, no traceability, copies sitting in other people’s inboxes.
What changed from the old act
The revision moved Swiss data protection closer to European standards without copying the GDPR. Four changes are noticeable in daily practice:
- Protection of legal entities was dropped. The act now covers data about natural persons only — a narrowing of scope, not an expansion.
- Genetic and biometric data are now expressly classified as sensitive personal data.
- Privacy by design and privacy by default are established as principles: data protection belongs in how a system is built, not in a notice added afterwards.
- The duty to inform when collecting personal data was significantly broadened — it now applies to collection generally, not only to sensitive data.
The penalty targets the person, not the company
This is the point missing from most summaries. The GDPR fines undertakings, scaled to group turnover. The revised FADP takes a different route: fines of up to CHF 250,000, directed at the responsible natural person.
For an SME that means the company does not pay — the individual responsible for the breach does, in practice often a member of management. The amounts are lower than under the GDPR; the personal exposure is far more direct.
Intent is required; negligent breaches are not caught in the same way. That eases the position for businesses making a genuine effort, and sharpens it for those knowingly leaving a known gap open.
What an average SME actually has to do
The effort is routinely overestimated, because GDPR material gets transposed onto Swiss circumstances. For a business without large-scale data processing it comes down to five things:
- A privacy notice stating plainly which data is processed for what purpose and who receives it — including disclosure abroad.
- Appropriate technical and organisational measures: access only for the people who need it, and the ability to withdraw it again.
- Contracts with processors. Anyone processing data on your behalf — hosting, accounting software, newsletter service — needs a contractual basis.
- A process for access requests. Data subjects are entitled to know what is held about them, and the deadline is tight if nobody has prepared.
- A reflex for the bad day: security breaches posing a high risk to the people affected must be reported to the FDPIC as soon as possible.
Disclosure abroad — and what it does not cover
Personal data may be disclosed abroad where the destination country ensures adequate protection; the Federal Council maintains a list. Absent adequacy, appropriate safeguards are needed — in practice usually standard contractual clauses.
A common misreading: these rules concern your own processors — where your data is hosted and processed. They are not triggered because your customer happens to use a foreign mail provider. The recipient’s choice is theirs, not a disclosure decision of yours.
The converse also holds: where you choose the storage location, you also choose how much work this proof becomes. That is the real argument for hosting in Switzerland — not the retention obligation, which despite widespread claims prescribes no location at all.
What this means for documents in a mailbox
The act prohibits no transmission channel. It requires measures appropriate to the risk. So the question is not whether email is permitted, but whether a mailbox is adequate control for the data in question.
For quotes, contracts and invoices containing personal data, the answer runs against the mailbox. An attachment, once sent, cannot be recalled. Copies sit in inboxes you do not control. Who opened or forwarded the document cannot be established. And access belongs to the person holding the mailbox rather than to the company — when they leave, the traceability leaves with them.
This is not a compliance catastrophe. It is a weakness of known size, and knowing it is already part of the organisational measure the act asks for.
Duties at a glance
| Duty | Applies to a typical SME | Note |
|---|---|---|
| Privacy notice / duty to inform | Yes | On any collection of personal data |
| Technical and organisational measures | Yes | Appropriate to the risk, not maximal |
| Processor contracts | Yes | Hosting, software, external service providers |
| Handling access requests | Yes | Prepare the process, do not improvise |
| Reporting security breaches | Only where risk is high | To the FDPIC, as soon as possible |
| Record of processing activities | Usually no | Exempt below 250 employees where risk is low |
| Data protection impact assessment | Usually no | Only for high-risk processing |
What athemi covers — and what it does not
athemi does not make you compliant. Compliance is a matter of process and documentation, not software. What athemi addresses is the technical part that most often fails in practice: customer documents travelling as attachments through mailboxes, where they end up belonging to nobody.
- Access is granted per project and can be withdrawn again — unlike a sent attachment.
- Traceable record of who opened and approved which document, and when.
- Access belongs to the company, not to one person’s mailbox.
- Hosted in Switzerland — here the storage location genuinely is the relevant argument.
- Not covered: your privacy notice, your record of processing, your processor contracts with third parties. Those need advice, not software.
Frequently asked
Does the GDPR or the FADP apply to us?
Possibly both. The FADP applies to processing connected to Switzerland. The GDPR applies in addition where you offer goods or services to people in the EU or monitor their behaviour. A Swiss SME with EU customers regularly sits under both regimes — the requirements largely overlap.
Do we need a data protection officer?
For private companies in Switzerland this is voluntary. The FADP recognises the role and attaches certain reliefs to it, but does not mandate it — unlike the GDPR in particular constellations.
What counts as sensitive personal data?
Among other things data on health, religious or political views, social assistance measures, administrative or criminal proceedings, and now genetic and biometric data uniquely identifying a person. In ordinary B2B work it rarely arises — in personnel files it regularly does.
Must we report every data incident?
No. Reportable breaches are those likely to result in a high risk to the personality or fundamental rights of the people affected. An appointment confirmation sent to the wrong address will not normally reach that threshold; open access to personnel files certainly does.
Related guides
-
The Swiss 10-year retention obligation, accurately
Ten years from the end of the financial year. What Art. 958f CO and the GeBüV actually require — and why the storage location is not prescribed.
-
Electronic signatures in Switzerland: which level do you actually need?
SES, AES or QES? Most business contracts are form-free — QES is needed only where the law prescribes written form. Includes a decision table.
-
Getting a quote signed off, digitally
How long does your quote bind you? Does it need a signature at all? Binding periods under the CO, the cost-estimate distinction, and documenting approval digitally.
Sources
This page summarises the legal position in general terms and is not legal advice. Whether and to what extent a duty applies to you depends on your specific processing.
Last reviewed: 2026-07-25